<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Site to Site down in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Site-to-Site-down/m-p/185166#M9117</link>
    <description>&lt;P&gt;What firmware release is being used here?&lt;BR /&gt;Also, have you attempted any debugging steps here?&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk62482" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk62482&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jun 2023 13:37:11 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-06-29T13:37:11Z</dc:date>
    <item>
      <title>VPN Site to Site down</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Site-to-Site-down/m-p/184893#M9116</link>
      <description>&lt;P&gt;Hi there to you all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I face a rather annoying situation.&lt;/P&gt;&lt;P&gt;Our client has bought several SMB Appliances for protection and safe routing through VPN Site to Site communication.&lt;/P&gt;&lt;P&gt;We implemented a Star network topology with those appliances.&lt;/P&gt;&lt;P&gt;The star is on our private cloud (it is on a vm) and the satellites are centrally managed through Smart-1 Cloud.&lt;/P&gt;&lt;P&gt;Well, everything was good till yesterday when the&amp;nbsp;VPN tunnel could not be established, the negotiation fails on Main Mode packet 5-6 with "INVALID-COOKIE".&lt;/P&gt;&lt;P&gt;Also, follow sk126092, it did not work for us.&lt;/P&gt;&lt;P&gt;The appliances were a cluster of two 1600 SMBs.&lt;/P&gt;&lt;P&gt;The weird thing is that inside the Smart-1 cloud says that it has "issues": "IPSec VPN blade is about to expire Jun 26, 2023 (Evaluation)" when on the appliance itself everything seems ok: "IPSec, expiration Never, Service CPSB-VPN"&lt;/P&gt;&lt;P&gt;I suspect that this is a glitch on Smart-1 Cloud because when I check "Licenses" in the tab below for each member of the cluster, it says that "127.0.0.1 Never&amp;nbsp;00-1C-...&amp;nbsp;&lt;SPAN&gt;CPAP-AP1600 CPSG-C-12-U CPSB-FW CPSB-VPN CPSB-IA CPSB-SSLVPN-500 CPSB-ADNC CPSB-ADNC-M..."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update: we are in the third "phase" of ecalation but with no result so far.&lt;/P&gt;&lt;P&gt;It seems that licensing "problems" is just "cosmetics" and nothing has to do with the real problem that causes the IKE rejection.&lt;/P&gt;&lt;P&gt;We have already renew our certificates to no avail,&lt;/P&gt;&lt;P&gt;we created brand new certificates and installed them also to no avail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please, we need your ideas!!!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Help!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 11:50:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Site-to-Site-down/m-p/184893#M9116</guid>
      <dc:creator>geza</dc:creator>
      <dc:date>2023-06-27T11:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to Site down</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Site-to-Site-down/m-p/185166#M9117</link>
      <description>&lt;P&gt;What firmware release is being used here?&lt;BR /&gt;Also, have you attempted any debugging steps here?&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk62482" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk62482&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 13:37:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Site-to-Site-down/m-p/185166#M9117</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-29T13:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to Site down</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Site-to-Site-down/m-p/185183#M9118</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi there PhoneBoy,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The current firmware version is&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;R81.10 (996000575)&lt;BR /&gt;I&amp;nbsp;&lt;/STRONG&gt;followed the steps on the sk, I had a session with a Checkpoint Engineer (3rd escalation) but to no avail&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your effort anyway,&lt;/P&gt;&lt;P&gt;I would appreciate any other ideas!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 15:47:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Site-to-Site-down/m-p/185183#M9118</guid>
      <dc:creator>geza</dc:creator>
      <dc:date>2023-06-29T15:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to Site down</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Site-to-Site-down/m-p/185205#M9127</link>
      <description>&lt;P&gt;Do you have the exact set of symptoms in sk126062?&lt;BR /&gt;Otherwise, those remediation steps won't work and deeper debugs will be required.&lt;BR /&gt;Did you actually take the debugs as specified in sk62482 and provide these to TAC?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 18:17:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Site-to-Site-down/m-p/185205#M9127</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-29T18:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to Site down</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Site-to-Site-down/m-p/185231#M9128</link>
      <description>&lt;P&gt;Yes and yes.&lt;/P&gt;&lt;P&gt;Thanks again for your effort!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 21:01:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Site-to-Site-down/m-p/185231#M9128</guid>
      <dc:creator>geza</dc:creator>
      <dc:date>2023-06-29T21:01:56Z</dc:date>
    </item>
  </channel>
</rss>

